CVE-2012-4404: Medium severity MoinMoin vulnerability
security/init.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
Other sources
security/init.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4404?
CVE-2012-4404 is classified as a medium severity vulnerability, which can allow unauthorized access to groups.
How do I fix CVE-2012-4404?
To fix CVE-2012-4404, upgrade to MoinMoin version 1.9.5 or later.
Who is affected by CVE-2012-4404?
CVE-2012-4404 affects MoinMoin versions 1.9.0 to 1.9.4, allowing remote authenticated users to gain improper group access.
What types of group names are involved in CVE-2012-4404?
The vulnerability involves group names that include virtual group names such as "All," "Known," and "Trusted."
Is authentication required to exploit CVE-2012-4404?
Yes, CVE-2012-4404 requires remote authenticated users to exploit the vulnerability.